VulnSea

n8n has 105 CVEs on record. Disclosure cadence is accelerating: 84 in the last 90 days against 20 in the 90 before. The busiest recent month was July 2026 with 53. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (15) and CWE-1321 (7). Most affected products: n8n (104), @n8n/computer-use (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
84 prev 20

Products

  • n8n 104
  • @n8n/computer-use 1
105
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

n8n vulnerabilities

CVEs affecting n8n, newest first. Open any entry for full detail, references, and exploit status.

105 CVEsRSS

CVE-2026-72762High· 8.8
1mo ago

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user abl…

▾ Twilightn8n · n8nEPSS 0.48%via NVD
GHSA-9cmh-xcqm-5hqrMedium
2mo ago

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

▾ Sunlitn8n · n8nvia GHSA
GHSA-jqwr-vx3p-r266Medium
2mo ago

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

▾ Sunlitn8n · n8nvia GHSA
GHSA-652q-gvq3-74qvMedium
2mo ago

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nvia GHSA
GHSA-fmvg-vhqq-r2mjMedium
2mo ago

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nvia GHSA
GHSA-5vfw-jc4p-fj39Medium
2mo ago

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

▾ Sunlitn8n · n8nvia GHSA
GHSA-h9fm-xcv2-qfw3Medium
2mo ago

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

▾ Sunlitn8n · n8nvia GHSA
GHSA-4v35-78jc-648rMedium
2mo ago

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · @n8n/computer-usevia GHSA
GHSA-88c4-pcqm-3r9pMedium
2mo ago

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

▾ Sunlitn8n · n8nvia GHSA
GHSA-gf29-4f56-r2jfHigh
2mo ago

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

▾ Twilightn8n · n8nvia GHSA
GHSA-vhf8-cg2h-cg3pMedium
2mo ago

n8n: SSRF Protection Bypass via MCP Client Node

n8n: SSRF Protection Bypass via MCP Client Node

▾ Sunlitn8n · n8nvia GHSA
GHSA-rcv6-pvrj-4xcgHigh
2mo ago

n8n: Authenticated code execution in the n8n Git node

n8n: Authenticated code execution in the n8n Git node

▾ Twilightn8n · n8nvia GHSA
GHSA-2x35-3fw4-9jr4High
2mo ago

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

▾ Twilightn8n · n8nvia GHSA
GHSA-gv7g-jm28-cr3mHigh
2mo ago

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

▾ Twilightn8n · n8nvia GHSA
GHSA-6qc9-mqvw-jg7xHigh
2mo ago

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

▾ Twilightn8n · n8nvia GHSA
GHSA-cj9h-qx8g-pq2gHigh
2mo ago

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

▾ Twilightn8n · n8nvia GHSA
GHSA-xmc9-4f2h-jf9cHigh
2mo ago

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

▾ Twilightn8n · n8nvia GHSA
GHSA-xwx6-jjhv-84p8High
2mo ago

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

▾ Twilightn8n · n8nvia GHSA
GHSA-hx4h-vr3m-45vhMedium
2mo ago

n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service

n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service

▾ Sunlitn8n · n8nvia GHSA
GHSA-pf2q-pxhf-hgmwMedium
2mo ago

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-59259Medium
2mo ago

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

▾ Sunlitn8n · n8nEPSS 0.44%via GHSA
CVE-2026-59257Medium
2mo ago

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nEPSS 0.57%via GHSA
CVE-2026-59254Medium
2mo ago

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

▾ Sunlitn8n · n8nEPSS 0.36%via GHSA
CVE-2026-59253Medium
2mo ago

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

▾ Sunlitn8n · n8nEPSS 0.28%via GHSA
CVE-2026-58661Medium
2mo ago

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

▾ Sunlitn8n · n8nEPSS 0.39%via GHSA
CVE-2026-65590Medium
2mo ago

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · n8nEPSS 0.58%via GHSA
CVE-2026-65594Medium
2mo ago

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

▾ Sunlitn8n · n8nEPSS 0.44%via GHSA
CVE-2026-65596Medium
2mo ago

n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

▾ Sunlitn8n · n8nEPSS 0.37%via GHSA
CVE-2026-65014Medium
2mo ago

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

▾ Sunlitn8n · n8nEPSS 0.59%via GHSA
CVE-2026-65589Medium
2mo ago

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nEPSS 0.48%via GHSA
n8n vulnerabilities (CVEs) — page 2 · VulnSea